forumNew topic

Hacker said 'I'll delete data if you don't pay' — did people who paid actually get data back?

ZZehra K***MemberCommunity member
Joined
Mar 2025
Message
86
#1

Company locked by ransomware. Hacker message says 'I'll delete data if you don't pay'. Will going to the police cause other issues? Is there insurance covering 'ransom payment'?

Is paying ransom illegal? Will we face sanctions? Some companies say 'paid but didn't get data back' while others say 'paid and recovered'. Is it really down to luck?

Are there other hackers who want to find you? If I pay, does my payment make me a target for other hackers?

NNazlı P***MemberCommunity member
Joined
Oct 2024
Message
9
Most Helpful#2

Paying ransom is legally and ethically controversial. There is no explicit ban criminalizing ransom payment in Turkey, but there are US/EU restrictions (counter-terrorism financing laws).

Cyber insurance: many policies cover 'ransom payment' costs, some don't. Check your policy. Important: whether the insurance (if any) negotiates with the hacker matters; paying without consultation might void coverage.

Result: paying ransom mostly fails (30-50% data recovery rate). There are legal, financial, and ethical risks.

UUfuk S***Veteran
Job title
Network Administrator
Sector
Furniture manufacturing
Organization type
workshop
Joined
Oct 2024
Message
187
#3

nobody will tell you to pay, but if you have insurance, insurance pays insurance negotiates with hacker. tbh dont pay with your own money

YYağmurNew member
Job title
Travel blogger
Joined
Oct 2024
Message
46
#4

There are many companies that paid and didnt get data back! Research it, 10 companies in Turkey filed lawsuits for this in 2024.

NNuri E***Expert
Job title
General coordinator
Sector
Leather
Organization type
regional distributor
Joined
Feb 2023
Message
386
#5

Most of the hacker's messages are just scare tactics. They said they'd delete the data, but they're actually selling the stolen data. It hasn't been deleted.

TTaner B***MemberCommunity member
Joined
Jun 2023
Message
4
#6

Statistically: 35% of ransomware victims paid the hacker, 50% of those got their data back, 50% didn't.

EEfe K***Member
Job title
Intern
Sector
Consulting
Organization type
early-stage startup
Joined
Nov 2023
Message
107
#7

Present this clearly to management: 'If we pay — 50% chance we don't get the data back + insurance coverage voided + risk of further attacks. If we restore from backup — we lose 2 weeks of data but the system is back up within a week.'

DDoruk U***Member
Job title
Technical service technician
Sector
Cosmetics
Organization type
two-branch business
Joined
Aug 2025
Message
137
#8

Let me speak from the other side; I'm on the supplier side. Taking notes for two weeks yields better results than a six-month estimate.

Having backups accessible on the same network and with the same identity makes them part of the target. If I were you, I'd go this route.

BBuseNew member
Job title
Fashion blogger
Organization type
early-stage startup
Joined
Sep 2024
Message
48
#9

there's a trap here, let me mention it then honestly if you don't write this down from the start it leads to arguments later.

just leaving this note it might be useful.

HHalil T***VeteranCommunity member
Joined
Oct 2023
Message
47
#10

Thanks a lot, I'll try it today. An untested backup is not a backup.

Proven by experience.

KKader C***Member
Job title
Studio Founder
Sector
Insurance
Organization type
chain store
Joined
May 2023
Message
166
#11

The opposite happened to me, that's why I'm writing. When you try to change everything at once, nothing settles.

Most incidents start with a leaked password, not a vulnerability. If you have questions, write them; I'll answer as best I can.

OOzanMember
Job title
Freelance designer
Joined
Apr 2024
Message
106
#12

Let me speak from the other side; I'm on the supplier side. The biggest time-waster for us was not knowing who had the final say.

People defend habits, not processes. Resistance comes from there. Just leaving this note, it might be useful.

MMelis Y***Member
Job title
Operations manager
Sector
Plastic
Organization type
8-person team
Joined
Jan 2023
Message
403
#13

Following. The biggest time-waster for us was not knowing who had the final say.

Trying to do this alone is the most expensive way. This is my opinion, I'm not claiming it's absolute truth.

AAyşegülMember
Job title
Boutique hotel
Organization type
workshop
Joined
Aug 2024
Message
86
#14

Let me write how its done in practice. like any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Solutions that work at a small scale collapse when you grow; I learned this late. tbh proven by experience.

MMerve Y***Member
Job title
Data Analyst
Sector
Energy
Organization type
120-person company
Joined
Apr 2023
Message
191
#15

We need to take it step by step. Having backups accessible on the same network and with the same identity makes them part of the target.

That's all, sorry if I went on too long.

HHüsniye Ç***MemberCommunity member
Joined
Oct 2024
Message
17
#16

theres a trap here let me mention it. mistakes made on the should i pay ransom side are usually reversible but expensive.

EEmre G***ExpertCommunity member
Joined
Jul 2024
Message
409
#17

There's a common mistake people make when doing this. People defend habits, not processes. Resistance comes from there.

Hope this helps.

PPerihan Y***MemberCommunity member
Joined
Aug 2024
Message
178
#18

Great work. Payment information changes are never verified through the channel they came from.

Proven by experience.

YYağmur C***MemberCommunity member
Joined
May 2023
Message
274
#19

I've been down this road, let me tell you. The biggest time-waster for us was not knowing who had the final say.

ŞŞerife G***ExpertCommunity member
Joined
Jan 2023
Message
201
#20

I agree. I mean security isn't absolute; it's about making attacks not worth the effort.

If you get three different answers on a topic, the question was asked wrong. Of course, it varies if your situation is different.

Reply